Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7hq-xhjg-3w36

Опубликовано: 02 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.
This bug only affects Firefox Focus. Other versions of Firefox are unaffected.. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.
This bug only affects Firefox Focus. Other versions of Firefox are unaffected.. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

EPSS

Процентиль: 24%
0.00079
Низкий

7.5 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

CVSS3: 7.5
redhat
больше 2 лет назад

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

CVSS3: 7.5
nvd
около 2 лет назад

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

CVSS3: 7.5
debian
около 2 лет назад

A lack of in app notification for entering fullscreen mode could have ...

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость полноэкранного режима браузера Mozilla Firefox, позволяющая нарушителю выполнить спуффинг-атаку

EPSS

Процентиль: 24%
0.00079
Низкий

7.5 High

CVSS3

Дефекты

CWE-290